#VU35777 Information disclosure in Pulse Connect Secure


Published: 2019-06-28 | Updated: 2020-08-08

Vulnerability identifier: #VU35777

Vulnerability risk: Medium

CVSSv3.1:

CVE-ID: CVE-2018-20811

CWE-ID: CWE-200

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Pulse Connect Secure
Server applications / Remote access servers, VPN

Vendor: Pulse Secure

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Pulse Connect Secure: 8.1 - 8.3


CPE

External links
http://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43877/


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability